# generic open
*.*.r=*
*.*.w=*
# lock down topp
topp.*.r=ADMIN
# but allow states to a specific user
# states is secret, only authenticated can read, only WRITER can write 
topp.states.r=READER